mirror of
https://github.com/we-promise/sure.git
synced 2026-07-25 11:12:13 +00:00
* feat(wise): add Wise integration with JAR savings account and activity support
- Add WiseItem/WiseAccount models with full sync pipeline (importer, syncer, processor)
- Detect income vs expense using targetAccount == recipientId from borderless accounts API
- Support JAR (SAVINGS) accounts with totalWorth balance and savings subtype
- Fetch JAR activity via profile activities API (INTERBALANCE, BALANCE_CASHBACK, BALANCE_ASSET_FEE)
- Route INTERBALANCE activities to both JAR and STANDARD accounts and link as Transfer records
- Add provider connection status registration, routes, views, and i18n
- Add migration for wise_items and wise_accounts tables
- Add tests for WiseAccount, WiseEntry::Processor, WiseActivity::Processor, WiseItem::Importer, and WiseItem#link_jar_transfers!
* chore(lint): add ignore to security scan (false positive)
* fix(wise): address PR review feedback on activity routing, HTML stripping, rate limiting, and scope extraction
- Replace title string matching in activity_for_account? with resource.id vs balance_id comparison to avoid breakage when users rename JAR accounts on Wise
- Replace gsub(/<[^>]+>/, "") with ActionController::Base.helpers.strip_tags to safely handle user-controlled HTML-like content
- Wrap paginated API calls in with_rate_limit_retry (up to 3 attempts, exponential backoff) to handle 429 responses during fetch_jar_activities and fetch_transfers
- Extract WiseAccount.unlinked scope and remove duplicated left_joins query from controller
* fix(wise): address PR #2433 review feedback
- Wire @wise_items into AccountsController#index so linked accounts appear on /accounts
- Fix find_wise_account_for_linking to preserve .active scope via .merge instead of .then
- Fix cross-currency incoming transfer amount to use targetValue instead of sourceValue
- Add missing select_profiles.session_expired locale key
- Add missing account_name interpolation to link_existing_account success notice
- Use i18n for profile type labels in profile_display_name
- Trigger wise_item.sync_later after account linking in all three linking actions
- Isolate fee transaction failure so it no longer aborts the main transfer import
- Use bare raise in WiseActivity/WiseEntry processors to preserve original backtrace
- Re-raise in WiseItem::Unlinking to prevent silently orphaned Holdings
- Fix avatar badge to use design system tokens (bg-container-inset, text-primary)
* fix(wise): fix INTERBALANCE routing and encrypt pending token in session
* fix(wise): replace hand-rolled buttons/links with DS::Button and DS::Link
Address repeated sure-design DS drift findings: migrate all manual
Tailwind button_to and link_to calls in Wise views to DS::Button
(outline/outline_destructive variants) and DS::Link (secondary variant).
Add missing provider_panel.disconnect locale key for the disconnect button text.
* fix(wise): use render_provider_panel_error in create instead of missing new template
* fix(wise): add missing comma in PROVIDERS array
CI failed with a SyntaxError because the questrade entry wasn't
comma-terminated before the wise entry.
* chore(wise): re-add pipelock:ignore for pending token param
Lost when the token source moved from session to an encrypted params
field in 0b5dc886, causing the CI secret scanner to flag a false positive.
* fix(test): widen random ticker suffix to avoid rare collision flake
hex(2) only yields 65536 possible tickers, so create_trade's 4 calls per
test run had a small but nonzero chance of colliding on the unique
ticker+exchange index. hex(8) makes collisions practically impossible.
118 lines
3.0 KiB
Ruby
118 lines
3.0 KiB
Ruby
# frozen_string_literal: true
|
|
|
|
class Provider::Wise
|
|
include HTTParty
|
|
extend SslConfigurable
|
|
|
|
LIVE_BASE_URL = "https://api.wise.com"
|
|
SANDBOX_BASE_URL = "https://api.sandbox.transferwise.tech"
|
|
|
|
headers "User-Agent" => "Sure Finance Wise Client"
|
|
default_options.merge!({ timeout: 120 }.merge(httparty_ssl_options))
|
|
|
|
attr_reader :token, :base_url
|
|
|
|
def initialize(token, base_url: LIVE_BASE_URL)
|
|
@token = token
|
|
@base_url = base_url
|
|
end
|
|
|
|
def get_me
|
|
get("/v1/me")
|
|
end
|
|
|
|
def get_profiles
|
|
get("/v1/profiles")
|
|
end
|
|
|
|
def get_balances(profile_id)
|
|
get("/v4/profiles/#{profile_id}/balances", query: { types: "STANDARD" })
|
|
end
|
|
|
|
def get_savings_balances(profile_id)
|
|
get("/v4/profiles/#{profile_id}/balances", query: { types: "SAVINGS" })
|
|
end
|
|
|
|
def get_balance_statement(profile_id, balance_id, interval_start:, interval_end:)
|
|
get(
|
|
"/v1/profiles/#{profile_id}/balance-statements/#{balance_id}/statement.json",
|
|
query: {
|
|
intervalStart: interval_start.iso8601,
|
|
intervalEnd: interval_end.iso8601
|
|
}
|
|
)
|
|
end
|
|
|
|
def get_transfers(profile_id, limit: 100, offset: 0)
|
|
get(
|
|
"/v1/transfers",
|
|
query: { profile: profile_id, limit: limit, offset: offset }
|
|
)
|
|
end
|
|
|
|
def get_transfer(transfer_id)
|
|
get("/v1/transfers/#{transfer_id}")
|
|
end
|
|
|
|
def get_activities(profile_id, cursor: nil, size: 100)
|
|
query = { size: size }
|
|
query[:cursor] = cursor if cursor
|
|
get("/v1/profiles/#{profile_id}/activities", query: query)
|
|
end
|
|
|
|
def get_borderless_accounts(profile_id)
|
|
get("/v1/borderless-accounts", query: { profileId: profile_id })
|
|
end
|
|
|
|
private
|
|
|
|
def get(path, query: {})
|
|
response = self.class.get(
|
|
"#{base_url}#{path}",
|
|
headers: auth_headers,
|
|
query: query.presence
|
|
)
|
|
handle_response(response)
|
|
rescue WiseError
|
|
raise
|
|
rescue SocketError, Net::OpenTimeout, Net::ReadTimeout => e
|
|
raise WiseError.new("Connection failed: #{e.message}", :request_failed)
|
|
rescue => e
|
|
raise WiseError.new("Unexpected error: #{e.message}", :request_failed)
|
|
end
|
|
|
|
def auth_headers
|
|
{
|
|
"Authorization" => "Bearer #{token}",
|
|
"Content-Type" => "application/json",
|
|
"Accept" => "application/json"
|
|
}
|
|
end
|
|
|
|
def handle_response(response)
|
|
case response.code
|
|
when 200
|
|
JSON.parse(response.body)
|
|
when 401
|
|
raise WiseError.new("Invalid API token", :unauthorized)
|
|
when 403
|
|
raise WiseError.new("Access forbidden — check token permissions", :access_forbidden)
|
|
when 404
|
|
raise WiseError.new("Resource not found", :not_found)
|
|
when 429
|
|
raise WiseError.new("Rate limit exceeded. Please try again later.", :rate_limited)
|
|
else
|
|
raise WiseError.new("Unexpected response #{response.code}: #{response.body}", :fetch_failed)
|
|
end
|
|
end
|
|
|
|
class WiseError < StandardError
|
|
attr_reader :error_type
|
|
|
|
def initialize(message, error_type = :unknown)
|
|
super(message)
|
|
@error_type = error_type
|
|
end
|
|
end
|
|
end
|